In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 16 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint. | |
| Title | Wago: Vulnerability in Smart Designer Web-Application | |
| First Time appeared |
Wago
Wago smart Designer |
|
| Weaknesses | CWE-203 | |
| CPEs | cpe:2.3:a:wago:smart_designer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wago
Wago smart Designer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-04-16T04:55:36.146Z
Reserved: 2023-10-31T07:22:47.201Z
Link: CVE-2023-5872
No data.
Status : Received
Published: 2026-04-16T05:16:12.373
Modified: 2026-04-16T05:16:12.373
Link: CVE-2023-5872
No data.
OpenCVE Enrichment
Updated: 2026-04-16T09:11:52Z
Weaknesses